THREAT OPS › Threat News › [GHSA] GHSA-c8qc-wf67-342w (medium) — Snipe-IT: Stored DOM XSS via table selected-count IDs
[GHSA] GHSA-c8qc-wf67-342w (medium) — Snipe-IT: Stored DOM XSS via table selected-count IDs
GHSA-c8qc-wf67-342w Severity: medium CVE: CVE-2026-61807
Snipe-IT: Stored DOM XSS via table selected-count IDs
### Impact The table component derives data-selected-count-id from the component $name value. On manufacturer and supplier detail pages, stored manufacturer or supplier names are passed into affected table components as that name value. The client-side JavaScript later reads the browser
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- b224cc636c6780386e3f73f03d1171f52ab4c37asha1
- d12ad3d53869443b96b663ba3ce2673ef343da71sha1
- CVE-2026-61807cve
Original source: https://github.com/advisories/GHSA-c8qc-wf67-342w